Introduction: From Freight Tracking to Distributed Corporate Management

Every export control regime in modern history has been, at bottom, a theory of geography. The Coordinating Committee for Multilateral Export Controls (CoCom) of the Cold War, the Wassenaar Arrangement that succeeded it in 1996, the Export Administration Regulations (EAR) administered by the U.S. Department of Commerce, and the International Traffic in Arms Regulations administered by the State Department all share a common architecture: a controlled item crosses a border toward a destination, and the license, the classification, and the enforcement action all attach to that crossing. The customs declaration, the bill of lading, the end-user certificate, and the shipping address are the load-bearing documents of the entire system. The paradigm assumes that possession follows delivery, that use follows possession, and that benefit follows use — a chain of inferences that held reasonably well when the controlled item was a machine tool bolted to the floor of an identifiable factory in an identifiable country.

That chain of inferences has now broken at every link. The central thesis of this paper is that the world’s most strategically consequential technology — the advanced accelerated-computing hardware that trains and serves frontier artificial intelligence systems — is governed by a control architecture designed for a world that no longer exists. High-performance hardware can today be purchased by a subsidiary incorporated in one country, financed by a holding vehicle in a second, installed in a leased data hall in a third, operated by engineers who log in from a fourth, and made to serve model outputs to beneficiaries in a fifth. Traditional strategic controls fail precisely because the technology can be operated remotely by foreign actors who never take physical possession of anything, and because corporate structures can be engineered so that no single national regulator ever sees the whole picture. The shipment clears customs lawfully; the evasion happens afterward, in the corporate registry and the network layer, where customs officers do not look.

This is the paradigm shift from physical cross-border freight tracking to distributed corporate management. It is not a marginal adjustment to an otherwise functional system. It is a change in the fundamental unit of analysis. The question that mattered in 1980 was “where is the box going?” The question that matters in 2026 is “who, across a lattice of entities in half a dozen jurisdictions, actually derives the computational benefit of the machine?” These are different questions, answered with different evidence, enforced through different instruments, and — as this paper will argue at length — the regulatory state has only just begun to admit that the second question is the real one.


Disaggregation of the Technical Stack

To see why the old question fails, one must first see how thoroughly the modern technology stack has been disaggregated. Consider a single hypothetical training cluster of ten thousand advanced GPUs, and enumerate the parties who touch it. There is the chip designer, an American firm. There is the foundry, in Taiwan. There is the server integrator, which may be American, Taiwanese, or Chinese-owned. There is the purchasing entity on the invoice — perhaps a Singapore-incorporated cloud company. There is the ultimate parent of that purchaser, which may sit in Beijing behind two or three intermediate holding companies in the British Virgin Islands or the Cayman Islands. There is the financing entity — a private-credit vehicle, a sovereign wealth fund, or a leasing company registered in a European financial hub. There is the data-center landlord in Johor or Batam, who owns the building but not the racks. There is the colocation tenant who owns the racks but not the workloads. There is the operator who administers the cluster. There are the remote users who submit the training jobs. And finally there are the beneficiaries of the model outputs — the entity whose product improves, whose research advances, whose capabilities compound because the cluster ran.

Corporate headquarters, subsidiaries, data-center tenants, beneficial owners, and physical workloads can thus be scattered across multiple countries simultaneously, and each scattering is individually lawful, commercially ordinary, and often tax-motivated rather than sanctions-motivated. That is what makes the phenomenon so difficult to police: the same architecture of holding companies, leasing structures, and offshore financing that global capitalism uses for entirely legitimate purposes is also, without modification, a near-perfect machine for dissolving export-control jurisdiction. The academic literature on compute governance has converged on the observation that computing power is unusually governable among AI inputs — it is detectable, excludable, and quantifiable, and it flows through an extremely concentrated supply chain[3] — but those properties attach to the physical chip. The corporate and contractual wrapper around the chip enjoys none of those properties. It is cheap to create, trivial to replicate, and can be re-papered in an afternoon.


The Regulatory Crossroads: The 2026 BIS Guidance

The events that crystallized this paper occurred over a single weekend at the end of May 2026. On Sunday, May 31, 2026, the Bureau of Industry and Security (BIS) at the U.S. Department of Commerce posted unusual weekend guidance clarifying that U.S. export license requirements for advanced computing items apply to entities headquartered in Country Group D:5 (which includes China) or Macau — or entities whose ultimate parent company is headquartered there — “even if the entities themselves are located outside” those jurisdictions[1]. In plain language: the license rule follows the company’s ultimate parent, not its postal address[4]. Reuters, which first reported the guidance, revealed that it had been posted after an unsigned paper circulated in Washington warning that America’s best AI chips had been flowing for nearly a year to the overseas subsidiaries of Chinese firms in places such as Malaysia; one chip-industry source with deep supply-chain knowledge estimated the volume in the hundreds of thousands of chips[2]. The circulating paper put the matter with memorable bluntness:

“the floodgates have quietly opened” [5]

— Unsigned policy paper circulated in Washington, dated May 29, 2026, quoted by Reuters  [5]

Two further details of the guidance are essential to everything that follows. First, the guidance was framed not as a new rule but as a clarification of a pre-existing requirement — an admission, in effect, that the requirement had gone unenforced for approximately a year after the Trump administration rescinded the Biden-era AI Diffusion Rule in May 2025 and left no worldwide licensing framework in its place[6]. Second, and most remarkably, the guidance did not require affected facilities to stop using hardware that had already been installed, nor did it cut off servicing of advanced computing items such as servers[2]. The chips that had already crossed were grandfathered in place. Former State Department technology official Chris McGuire captured the enforcement community’s alarm within hours:

“This is a HUGE problem” [2]

— Chris McGuire, former U.S. State Department official specializing in technology and national security  [2]

McGuire went on to observe that Chinese companies had very likely been buying restricted Blackwell-class processors at scale through overseas subsidiaries, and that even the new guidance left open a parallel gap concerning enhanced due-diligence obligations at the foundry level[6]. Nvidia, for its part, responded that its own vetting already operated on the parent-company principle:

“licences are required to ship controlled products to PRC-headquartered companies” [7]

— Nvidia spokesperson, statement to Al Jazeera, June 1, 2026  [7]

A two-page weekend notice thus became, arguably, the most important export-control document of the decade — not because of what it changed, but because of what it conceded. It conceded that the destination-based control model had been outflanked by corporate structure; that the outflanking had operated at industrial scale; and that the remedy on offer (prospective licensing plus retrospective grandfathering) locked in the very compute pools it was meant to prevent. The 2026 guidance is therefore the regulatory crossroads at which this paper stands: the moment the United States formally admitted that jurisdiction had decoupled from geography, without yet building the machinery to re-couple them.


Why This Framework Is Named “Export Evasion”

A word is owed on the title, because the choice is deliberate and carries the paper’s central argument inside it. I name this framework Export Evasion for four reasons.

First, because the object of evasion is jurisdiction itself, not merely a shipment. The classical vocabulary of enforcement — smuggling, diversion, transshipment — describes the movement of a physical item to a prohibited place. Much of what this paper documents involves no prohibited movement at all. The chips land, entirely lawfully, in Kuala Lumpur or Singapore or Abu Dhabi; what is evaded is the reach of the rule, accomplished by arranging ownership, financing, and operation so that the rule’s trigger — the destination — never fires. “Export evasion” names the evasion of the export-control system as a system, in the same way that “tax avoidance” names the lawful engineering-around of a tax code rather than any single fraudulent return.

Second, because the term deliberately spans the licit-illicit spectrum. The phenomenon runs from outright criminal smuggling (falsified shipping documents, relabeled hardware, dummy audit equipment) through gray-zone structures (shell purchasers, nominee directors, layered offshore parents) to fully lawful arrangements (a legitimate multinational subsidiary buying hardware for its own regional business) that nonetheless produce the identical strategic outcome: restricted actors obtaining the benefit of restricted compute. A framework that captured only the criminal tail would miss the much larger lawful body. “Evasion” is the only word broad enough to hold the whole spectrum while still naming the strategic effect.

Third, because the word relocates the analytical burden from the border to the balance sheet. To ask “was this export evaded?” in the sense meant here is to ask a set of questions that customs paperwork cannot answer — questions about ownership chains, financing flows, operational control, and workload benefit. Naming the framework “Export Evasion” forces the regulator, the compliance officer, and the scholar to interrogate the corporate and computational layers where the modern evasion actually occurs.

Fourth, because history will likely remember 2024–2026 as the era in which evasion outran enforcement, and the name should say so plainly. The Financial Times has reported that more than $1 billion of controlled Nvidia processors reached China in a single three-month window[8]; Reuters has reported that DeepSeek trained on smuggled Blackwell hardware[8]; and the U.S. government itself has now conceded the subsidiary loophole in writing[1]. A paper about this period that chose a gentler title would be committing, in miniature, the same evasion it seeks to describe.


The Export Evasion Test

Against the single legacy question — where is the box going? — this paper proposes a six-question test that any serious control regime, corporate compliance program, or academic analysis must now be able to answer. The test recurs throughout the paper and is operationalized in Section 6 as the Beneficial Workload Rule.


Exhibit A — The Export Evasion Test: Six Questions That Replace the Shipping Address

#QuestionWhat It RevealsLegacy Blind Spot
1Who owns the customer?Ultimate beneficial ownership and parent-company lineage behind the purchasing entityEnd-user certificates stop at the first corporate layer
2Who finances the purchase?The capital chain — leasing vehicles, private credit, sovereign funds — that reveals the real principalFinancing entities are invisible to export licensing
3Who operates the cluster?Administrative and root-level control of the installed hardwareOperations occur after delivery, outside customs jurisdiction
4Who controls the workloads?The party that decides what is trained, tuned, and run on the machinesRemote job submission crosses no physical border
5Who receives the model outputs?The downstream beneficiary of weights, checkpoints, and inferenceModel artifacts leave on a hard drive or an API call, not a pallet
6Who maintains and services the equipment?The vendor relationship that keeps restricted hardware operational for yearsPost-installation servicing was never treated as a controlled event

The remainder of the paper proceeds in six sections. Section 1 reconstructs the evolution of end-use and end-user frameworks and shows why the static, list-based architecture inherited from Wassenaar cannot see digital access. Section 2 dissects the anatomy of modern corporate group separation — entity disaggregation, geographic arbitrage, and shell architecture. Section 3 provides a deep reading of the 2026 Commerce Department pivot, including its extraterritorial logic and its grandfathering boundaries. Section 4 grounds the analysis in the Southeast Asian transshipment record, with Malaysia as the central case. Section 5 widens the lens to geopolitical lawfare: strategic hubbing in the Gulf, sovereign friction in intermediary states, and Beijing’s counter-regulatory escalation. Section 6 distills the lessons into six institutional pillars, culminating in the proposed Beneficial Workload Rule, before the Conclusion returns to the naming of the framework and the future of controls that must follow capital, lineage, and workloads rather than freight.


Section 1: The Evolution of End-Use and End-User Frameworks

No one can understand why the current system fails without first understanding why it once succeeded, and for whom it was built. Export controls are not a modern invention layered onto globalization; they are a Cold War institution that globalization was later permitted to grow around. The purpose of this section is to reconstruct that institutional history with enough care to identify precisely which assumptions were load-bearing — and therefore precisely where the structure cracked when high-performance computing, cloud leasing, and multinational corporate engineering arrived simultaneously in the 2020s. The deep explanation matters because the policy community’s instinct, when confronted with each new evasion episode, has been to patch the list — add an entity here, lower a performance threshold there — when the defect lies not in any list but in the geometry of the framework itself.


1.1 The Historical Baseline: Point-to-Point Controls and the Physics of the Border

The classical export-control model is best described as point-to-point: a controlled item departs point A, in the controlling state, and arrives at point B, in the destination state, and the entire regulatory apparatus is organized around observing and licensing that single arc. CoCom, founded in 1949, embargoed defined categories of strategic goods to the Soviet bloc on exactly this logic, and it worked — imperfectly, but genuinely — because the goods in question had properties that cooperated with the model. A precision five-axis milling machine is heavy, rare, hard to disguise, harder to relocate, and useless without on-site installation, calibration, and spare parts. Its export is an event; its use is stationary; its benefit is local. Under those physical conditions, controlling the border really did mean controlling the technology, and the end-use statement signed at the point of sale bore a plausible relationship to the machine’s actual life.

The U.S. system elaborated this baseline into the architecture still in force today: the Commerce Control List classifying items by Export Control Classification Number; country groups arraying destinations by risk; the Entity List naming specific bad actors; end-use and end-user controls attaching obligations to what the buyer says it will do; and the “knowledge” standard limiting exporter liability to what the exporter knew or had reason to know[9]. Each element presumes the point-to-point arc. The Entity List names entities at addresses. The country groups grade territories. The end-user certificate describes a place of use. Even the Foreign Direct Product Rule — the most aggressively extraterritorial instrument in the kit, which extends U.S. jurisdiction to foreign-made items produced with U.S. technology — still ultimately polices a shipment toward a destination[9]. The system’s reach expanded enormously between 2018 and 2024, but its geometry never changed.

The October 7, 2022 controls on advanced computing and semiconductor manufacturing items were the apex of this architecture — what Gregory C. Allen of the Center for Strategic and International Studies called a genuine landmark in U.S.-China relations, a deliberate strategy of denying China the future of AI by holding a small number of supply-chain chokepoints[10]. The controls were tightened in October 2023 (closing performance-density workarounds), again in December 2024 (adding roughly 140 entities and extending the Foreign Direct Product Rule through a new Footnote 5 regime), and repeatedly through 2025[9]. Yet each tightening remained faithful to the same premise: identify the item, identify the destination, license the arc. Chris Miller of Tufts University’s Fletcher School — whose Chip War became, as one 2026 profile observed, the reference text of the entire chokepoint strategy — has consistently emphasized how much of the strategy’s force depends on the concentration of the supply chain rather than on the paperwork of the border, and his own framing has evolved from keeping China “a generation behind” toward the contest over aggregate computing power[11]. That evolution in the leading scholar’s thinking is itself evidence of the shift this paper describes: when the metric becomes aggregate compute rather than frontier node access, the location of any individual box matters far less than the sum of workloads a state can command.


1.2 Static Framework Limitations: Wassenaar and the List-Based Mind

The multilateral layer is weaker still. The Wassenaar Arrangement, the 42-participant successor to CoCom, was designed for a post-Cold War world in which no single adversary was named and no member was bound: it harmonizes control lists by consensus, updates them on an annual diplomatic cycle, and leaves licensing decisions entirely to national discretion. Three structural defects follow, each fatal to controlling dynamic digital access.

First, temporal mismatch. A consensus list amended once a year cannot track a technology whose defining performance metrics double on an eighteen-month cadence and whose leading products iterate faster than the diplomatic calendar. By the time a chip generation is described in an agreed control entry, its successor is shipping and its predecessor is being resold on secondary markets. Second, categorical mismatch. Wassenaar controls items — goods, software, technology — and was never designed to control services, access, or capacity. Renting time on a cluster is none of the things the lists describe, which is precisely why the scholarly literature identified cloud access as the natural bypass of the October 2022 controls almost immediately: the controls covered the physical export, re-export, and in-country transfer of items, and not the provision of services that use those items[12]. Third, membership mismatch. Russia remains a formal Wassenaar participant, and the key transshipment and hosting jurisdictions of the 2020s — Malaysia, Singapore, Indonesia, Thailand, the Gulf states, much of Central Asia — are not members at all. The multilateral instrument thus binds the wrong countries at the wrong speed about the wrong things.

The consequence is that the United States has been driven to act unilaterally and extraterritorially — through the Foreign Direct Product Rule, through bilateral alignment with Japan and the Netherlands on manufacturing equipment[9], and ultimately through the 2026 parent-company guidance — while the formal multilateral regime looks on. Every unilateral extension solves an immediate leak and simultaneously deepens the sovereignty frictions examined in Section 5. This is the strategic trap of the list-based mind: it can only respond to a structural problem by lengthening the list.


1.3 Digital Demarcation: From “Where the Box Lands” to “Who Logs Into the Server”

The decisive conceptual transition of the 2020s — what this paper calls the digital demarcation — is the movement of the control question from “where does the box land?” to “who logs into the server?” The transition was visible in the scholarship years before it was visible in the regulations. Georgetown’s Center for Security and Emerging Technology, in its two-part 2023 analysis of cloud access, concluded that using the Export Administration Regulations as they stood to control the sale of advanced cloud computing services to Chinese users was fraught with loopholes, and flagged the policy options — making Infrastructure-as-a-Service directly controllable under the EAR, and imposing know-your-customer rules on cloud providers — that would dominate the debate for the next three years[12]. Janet Egan and Lennart Heim, in the same period, formalized the KYC scheme for compute providers, observing that cloud access, unlike an exported chip, offers a precise and flexible control surface: digital access provides only point-in-time compute that can be throttled or revoked, whereas a physically exported chip can never be retracted[13]. The compute-governance research program summarized in the 2024 multi-institution paper co-authored by, among others, Gillian Hadfield and Yoshua Bengio, supplied the theoretical foundation — compute as the detectable, excludable, quantifiable input flowing through a concentrated supply chain[3]. As Heim and colleagues put it in the essay indexed by MIT’s political-science cyber program:

“Compute governance is a particularly important approach to AI governance because it is feasible” [14]

— Lennart Heim, Markus Anderljung & Haydn Belfield, “To Govern AI, We Must Govern Compute”  [14]

Regulation lagged the scholarship by years, and the lag is itself instructive. In January 2024, the Commerce Department issued a proposed rule — flowing from the 2023 AI executive order — that would have required U.S. IaaS providers to verify the identities of foreign customers and report large AI training runs; the rule generated extensive industry comment and was never finalized into an operating regime[15]. In December 2025, Senators Dave McCormick and Ron Wyden introduced the Remote Access Security Act to amend the Export Control Reform Act of 2018 so that remote access to controlled technology through cloud infrastructure would itself be a controlled event — an explicit legislative admission that under current law, foreign actors can train AI models on U.S.-jurisdiction chips without any license requirement attaching at all[16]. Senator Wyden’s framing was categorical:

“Foreign countries shouldn’t be able to end-run export bans on American technology” [16]

— Senator Ron Wyden (D-OR), co-sponsor, Remote Access Security Act, December 17, 2025  [16]

Senator McCormick’s accompanying statement made the enforcement gap explicit: bad actors can train AI models by accessing advanced chips under U.S. jurisdiction, and the Bureau of Industry and Security has no authority to require a license for the access itself[16]. As of this writing in July 2026, the bill remains pending — which means that the digital demarcation has been fully mapped by scholars, fully conceded by legislators, and still not fully enacted by the state. The table below summarizes the three eras this section has traversed.


Table 1 — Three Eras of Export Control Logic

DimensionEra I: Point-to-Point (1949–2013)Era II: Entity & Chokepoint (2014–2024)Era III: Jurisdictional Decoupling (2024– )
Unit of controlThe shipmentThe listed entity / the chokepoint technologyThe corporate group and the workload
Key documentBill of lading; end-user certificateEntity List entry; ECCN thresholds; FDPRUltimate-parent lineage; cloud contract; attestation log
TriggerBorder crossingNamed party or performance thresholdHeadquarters, ownership, financing, access, benefit
Enforcement locusCustoms at the portExporter due diligence; BIS licensingRegistries, cloud providers, hardware telemetry, post-import audit
Signature failureThird-country re-exportFront companies just below thresholdsLawful subsidiaries and rented clusters delivering restricted benefit
Emblematic instrumentCoCom lists; Wassenaar ArrangementOct. 7, 2022 controls; Footnote 5 FDPRMay 31, 2026 BIS parent-company guidance; Chip Security Act

The section’s conclusion can be stated in one sentence: the end-use and end-user frameworks did not fail because they were badly administered; they failed because the thing they were built to observe — the decisive border crossing — stopped being where the decisive events occur. Section 2 turns to the corporate machinery that moved those events out of sight.


Section 2: Anatomy of Modern Corporate Group Separation

If Section 1 explained why the border stopped mattering, this section explains what replaced it: the deliberately distributed corporate group. The modern multinational is not a single legal person with foreign branches; it is a constellation of dozens or hundreds of legal persons, each domiciled where its function is cheapest, safest, or least visible, bound together by ownership chains, intercompany contracts, and capital flows that no single regulator can see end to end. This is the terrain on which Export Evasion actually operates, and it must be understood in its full, mundane ordinariness before its strategic exploitation can be understood. The deep explanation here is deliberately patient, because the single most common analytical error in this field is to treat every offshore subsidiary as a shell and every shell as a crime. The reality is a spectrum — and it is precisely the lawful end of the spectrum that does the heaviest strategic work.


2.1 Entity Disaggregation: Holding Company, Operator, Tenant, Lessee, Owner

Begin with the taxonomy. A holding company owns equity and does nothing else; it is a filing cabinet with a board. An operating subsidiary employs people, signs customer contracts, and holds licenses. A hardware lessee rents servers it does not own, often from a leasing entity whose entire function is to hold depreciating assets off the operator’s balance sheet. A data-center tenant rents space, power, and cooling in a building owned by a landlord who never touches the IT load. A beneficial owner is the natural person or ultimate parent that, behind however many layers, enjoys the economic fruits. In a typical AI-infrastructure transaction of 2025–2026, every one of these roles is held by a different legal entity, frequently in a different jurisdiction, and export-control obligations attach cleanly to none of them except the first purchaser named on the export documentation.

This disaggregation is what allowed the subsidiary loophole of 2025–2026 to operate at scale without any single participant necessarily committing an offense. The chip vendor sold to a Singapore or Malaysia entity that was not on the Entity List. The entity was not lying about its address; it genuinely operated a data hall in Johor. The data hall genuinely served customers. The customers’ ultimate parents sat in China — a fact that lived in a foreign corporate registry, outside the vendor’s end-user certificate and outside the customs declaration entirely. The May 2026 BIS guidance exists precisely because this chain of individually unremarkable facts summed to a strategically decisive outcome: the guidance had to state, in writing, that a license is required for entities headquartered in D:5 jurisdictions or whose ultimate parent is headquartered there, wherever the entity itself sits[1] — because nothing in the operational paperwork of the preceding year had forced anyone to look up the chain.

It must be stressed — and this paper stresses it repeatedly — that the distinction between a shell company and a legitimate multinational subsidiary is real, consequential, and genuinely difficult to draw at the moment of transaction. A Chinese cloud firm’s Singapore subsidiary with three hundred employees, real revenue, and a real regional customer base is not a shell; it is exactly the kind of entity the global trading system was built to encourage. Yet from the standpoint of the Export Evasion test, its purchases can deliver restricted compute benefit to its restricted parent just as surely as a brass-plate company in Labuan can. The legal form differs; the strategic function converges. Any control regime that can only see the brass plate will systematically miss the larger channel.


2.2 Geographic Arbitrage: Financing in EMEA, Infrastructure in Southeast Asia, Design Everywhere

Layered over entity disaggregation is geographic arbitrage: the systematic exploitation of differences between national legal regimes by assigning each corporate function to the jurisdiction that treats it most favorably. The pattern in advanced-computing ecosystems by 2026 is remarkably consistent. Financing and treasury functions concentrate in EMEA financial hubs and offshore centers — Luxembourg, Ireland, the Netherlands, the Gulf, the Caribbean dependencies — where capital-markets access, tax treaties, and creditor protections are optimal and where export-control scrutiny of money is essentially nil. Physical data infrastructure concentrates in Southeast Asia — Johor, Batam, greater Kuala Lumpur — where land, power, and construction are cheap, where subsea-cable connectivity to both East Asia and the West is excellent, and where, until mid-2025, no domestic permit regime governed the onward movement of U.S.-origin accelerators at all[17]. Design centers, sales offices, and research staff scatter globally along talent lines. The result is a corporate organism whose capital answers to one sovereign, whose hardware sits under a second, whose people work under a third, and whose benefit flows to a fourth — an organism that no destination-based rule can grip, because it has no single destination.

The macroeconomic literature has begun to measure what this arbitrage costs and what its forced unwinding would cost. The International Monetary Fund’s staff work on geoeconomic fragmentation estimates that trade fragmentation alone could shave between 0.2 and 7 percent from global output depending on severity, and that technological decoupling amplifies the losses to 8–12 percent of GDP in some countries[18]. Gita Gopinath, the Fund’s First Deputy Managing Director, delivering the message at Stanford’s Institute for Economic Policy Research, was blunter still:

“A very serious decoupling scenario could cost up to 7 percent of [global] GDP” [19]

— Gita Gopinath, First Deputy Managing Director, International Monetary Fund, speaking at Stanford (SIEPR)  [19]

And in earlier remarks she warned that mismanaged fragmentation could

“reverse nearly three decades of peace, integration, and growth” [20]

— Gita Gopinath, IMF, remarks reported by Reuters  [20]

The IMF’s numbers matter to this paper for a reason beyond scene-setting: they quantify the incentive gradient that guarantees geographic arbitrage will continue. When the cost of full decoupling runs to several points of world GDP, every firm, every intermediary state, and often every fragment of the controlling state’s own government has an enormous economic incentive to find the arrangement that preserves the flows while satisfying the letter of the rules. Arbitrage is not a bug in the system that better drafting will remove; it is the equilibrium behavior of rational actors facing trillions of dollars of foregone surplus. Control design that ignores this gradient — that assumes compliance will be volunteered against interest — is designing for a species that does not exist.


2.3 Shell Architecture: How Nested Entities Defeat Automated Triggers

At the gray and dark end of the spectrum sits deliberate shell architecture: the engineering of ownership chains specifically to defeat screening. The techniques are well documented in the enforcement record of 2024–2026 and deserve technical description, because each defeats a specific automated trigger in a specific way.

Nesting stacks holding companies three to six layers deep across registries that do not share data — a Malaysian operating company owned by a Singapore holding company owned by a BVI vehicle owned by a Cayman trust — so that any single-registry lookup terminates before reaching the true parent. Nominee substitution places local directors and shareholders of convenience on the visible documents. Name-distance ensures the purchasing entity shares no string, no address, and no officer with any listed entity, defeating the fuzzy-matching screens that compliance software runs against the Entity List. Age-washing uses shelf companies with years of dormant history, because screening tools weight newly incorporated purchasers as risky. Trade-description laundering declares AI servers as ordinary “computer components,” as in the 2026 Malaysian free-trade-zone seizure in which a shipment was staged for re-export precisely to strip its origin before continuing onward[21]. And structural mimicry — the most sophisticated technique — builds an entity that is not merely papered but real: staffed, revenue-generating, audit-passing, and still, functionally, a conduit. The criminal cases of the period display the full toolkit: the Texas-based Hao Global operation pleaded guilty in late 2025 — the first-ever U.S. conviction in an AI-technology smuggling case — to moving $160 million of Nvidia H100 and H200 processors to China using falsified documents and relabeled hardware[21]; the March 2026 indictment of a Super Micro co-founder alleged diversion of GPU-equipped servers through Taiwan and Southeast Asian intermediaries using faked documents and dummy equipment staged to pass audits[22].

What makes shell architecture so durable is that the international transparency infrastructure that should defeat it has been moving backward. The U.S. Corporate Transparency Act — enacted in 2021 to build a beneficial-ownership registry precisely so that layered anonymity would fail — saw the Treasury Department announce in March 2025 that it would not enforce the reporting rule against domestic companies and their beneficial owners[23], and by 2026 the Government Accountability Office was formally warning that expanded exemptions had left material gaps in the ownership information available to law enforcement[24]. The Financial Action Task Force has for years graded the United States poorly on exactly this dimension[23]. The strategic irony is severe: at the precise moment Washington asserted, through BIS, that ultimate parentage is the trigger for the world’s most sensitive technology controls, it was dismantling the domestic machinery for knowing who ultimate parents are. Section 6’s first pillar returns to this contradiction. The table below consolidates the anatomy this section has dissected.


Table 2 — Anatomy of a Disaggregated Advanced-Computing Group (Stylized Composite, 2025–2026)

Corporate RoleTypical JurisdictionVisible ToExport-Control Exposure Under Legacy Rules
Ultimate parent / beneficial ownerChina (or layered via BVI / Cayman)Home-country registry onlyNone, unless separately listed
Intermediate holding vehiclesBVI, Cayman, Labuan, LuxembourgOffshore registries; often opaqueNone
Financing / leasing entityLuxembourg, Ireland, Gulf, SingaporeLenders and auditorsNone — capital is uncontrolled
Purchasing entity on invoiceSingapore, MalaysiaVendor KYC; customsFull — but screens only this layer
Data-center landlordMalaysia (Johor), Indonesia (Batam)Local planning and utility bodiesNone
Colocation tenant / operatorSingapore-managed, Malaysia-sitedLandlord; local telecom regulatorMinimal — post-import activity
Remote workload controllersChina (VPN / dedicated links)Effectively no oneNone under pre-2026 rules
Output beneficiariesChinaNo oneNone — model weights are not on the CCL

Section 3: The 2026 Commerce Department Regulatory Pivot

Regulatory documents rarely repay close reading; the May 31, 2026 BIS guidance repays it richly, because nearly everything important about it lies in what it implies rather than what it commands. This section performs that close reading in three movements: the mandate itself and the year-long vacuum that made it necessary; the extraterritorial logic by which corporate lineage displaced facility location as the jurisdictional trigger; and the enforcement boundary — the grandfathering of installed infrastructure — that converts the guidance from a wall into a ratchet. Throughout, the section situates the guidance within the oscillating policy sequence of 2025–2026, because the guidance cannot be understood as a single decision; it is the seventh or eighth move in a rapid, internally contradictory sequence that itself constitutes evidence for this paper’s thesis that the control system is improvising on a collapsed foundation.


3.1 The Mandate and the Vacuum That Preceded It

The sequence begins in January 2025, when the outgoing Biden administration issued the Framework for Artificial Intelligence Diffusion — a worldwide, three-tier licensing architecture that capped advanced-accelerator flows to Tier 2 countries; Malaysia’s allocation, for illustration, was capped at 50,000 GPUs over two years[25]. In May 2025, the incoming Trump administration announced the rule would not take effect, preferring bilateral “compute diplomacy” deals to a global framework — and thereby, without intending to, opened a twelve-month vacuum in which no worldwide destination framework governed advanced accelerators at all[6]. Chinese cloud and AI firms read the vacuum accurately and moved through it at speed: standing up data-center capacity in Singapore, Malaysia, and Indonesia through overseas subsidiaries and purchasing restricted-class hardware in quantities that the industry source cited by Reuters placed in the hundreds of thousands of units[2]. Through late 2025 and early 2026, the policy oscillation continued: a December 2025 relaxation permitted certain H200-class exports to China; a final rule effective January 15, 2026 formalized a licensing posture under which approved China/Macau shipments of a given chip could not exceed 50 percent of the exporter’s U.S.-bound volume of that product[26]; and in January 2026 Reuters reported Chinese authorities had confirmed purchase approvals exceeding 400,000 H200 units for ByteDance, Alibaba, and Tencent even as Beijing simultaneously steered its champions toward domestic silicon[27]. It was against this churn that the unsigned loophole paper circulated in Washington at the end of May, and the Sunday guidance followed within seventy-two hours[2].

The guidance itself is two pages. It states that BIS license requirements for covered advanced computing items apply to any entity headquartered in Country Group D:5 or Macau, or any entity whose ultimate parent company is headquartered there, even where the entity itself is located elsewhere[1]. It was issued, BIS said, in response to questions about whether pre-existing license requirements were being enforced after the AI Diffusion framework’s rescission[7]. Read carefully, that is an extraordinary sentence for a regulator to publish: it concedes that the requirement pre-existed, that the market doubted it was operative, and that the doubt was reasonable enough to require a formal answer. The guidance is thus best understood not as rulemaking but as confession — the moment the enforcement gap of 2025–2026 became official record. As the White House’s own technology-policy leadership had framed the underlying doctrine the previous summer:

“The highest-end semiconductors need to continue to be export-controlled and not allowed into China” [28]

— Michael Kratsios, Director, White House Office of Science and Technology Policy, at CSIS  [28]

The doctrine, in other words, never changed. What changed — what the guidance was forced to admit — was that for a year the doctrine and the enforcement had parted company, and corporate structure had flowed through the gap.


3.2 Extraterritorial Jurisdiction: Lineage Over Location

Doctrinally, the guidance completes a two-decade migration of the jurisdictional trigger. Classical controls asked where the item goes. The Entity List era asked who the named counterparty is. The Foreign Direct Product Rule asked what technology made the item. The 2026 guidance asks a fourth and more radical question: whose corporate bloodline does the counterparty carry? Ownership and parent lineage now take precedence over the physical location of the facility — a Malaysian data hall owned by a Chinese parent is, for licensing purposes, treated according to the parent’s headquarters, not the hall’s postal code[4]. This is extraterritoriality of a new kind. The FDPR projected U.S. jurisdiction along the supply chain of production; the parent-company rule projects it along the chain of ownership. The first follows the technology forward; the second follows the capital backward.

Three consequences deserve emphasis. First, the rule transforms compliance from a customs exercise into a forensic corporate-intelligence exercise. An exporter can no longer discharge its knowledge obligations by screening the invoice name against the Entity List; it must now establish, for every material counterparty, an ultimate-parent determination that may run through offshore registries that publish nothing — and it must keep that determination current as ownership changes. The practical burden was visible within weeks: Nvidia, reportedly, cut more than half of its Asian chip buyers and dispatched staff to conduct physical data-center visits in Singapore, Malaysia, and Japan as it rebuilt its vetting around the parentage principle[21]. Second, the rule internationalizes the compliance perimeter without internationalizing the enforcement apparatus: the entities now swept in are creatures of Malaysian, Singaporean, and Emirati law, yet the obligations that bind their suppliers are American, enforced through the long levers of U.S. supply-chain dominance rather than through any treaty. Third — and this is the deepest point — the rule tacitly adopts half of this paper’s Export Evasion test. “Who owns the customer?” is now, officially, a licensing question. But questions two through six — financing, operation, workload control, output benefit, servicing — remain outside the trigger. The 2026 pivot reached the corporate registry; it has not yet reached the workload. Section 6 completes the journey the guidance began.


3.3 Enforcement Boundaries: The Grandfathering Choice

The most consequential sentence in the guidance is the one describing what it does not require: data centers holding already-installed hardware need not stop using it, and servicing of installed advanced computing items may continue[2]. The regulatory logic is intelligible — retroactive dispossession of lawfully acquired property would trigger ferocious diplomatic and commercial resistance from the host states whose cooperation Section 5 shows to be indispensable, and would expose the entire compute-diplomacy agenda to charges of confiscation. But the strategic arithmetic is unforgiving. If the mid-range estimate of the leakage is credited — hundreds of thousands of Blackwell- and Hopper-class accelerators[2] — then the grandfathered stock constitutes, in aggregate, one of the largest AI training resources on Earth, permanently domiciled beyond the rule’s reach and refreshed by permitted servicing for the multi-year life of the silicon. The guidance closed the gate and deeded the pasture.

This grandfathering choice also created a precedent with game-theoretic teeth: it taught every future evader that speed is amnesty. Whatever crosses before the next clarification will, on the 2026 precedent, likely keep running after it. The vendor-responsibility question compounds the problem. Advanced clusters are not passive property; they require firmware updates, failure-part replacement, interconnect maintenance, and thermal management from the vendor ecosystem on an ongoing basis. By permitting continued servicing, the guidance made the U.S. vendor ecosystem a standing participant in the operation of the very compute pools the licensing rule condemns — an arrangement examined further in Sections 4 and 6, where post-installation vendor responsibility becomes a pillar of the proposed framework. The timeline below fixes the whole oscillating sequence for reference.


Table 3 — The Regulatory Oscillation, January 2025 – July 2026

DateActionEffect on the Evasion Surface
Jan 2025Biden administration issues AI Diffusion Rule (three tiers; e.g., Malaysia capped at 50,000 GPUs / 2 years)Worldwide destination framework announced but never operative
May 2025Trump administration rescinds AI Diffusion Rule; pivots to bilateral compute diplomacyTwelve-month vacuum opens; subsidiary channel scales
Jul 14, 2025Malaysia (MITI) Directive 1/2025: Strategic Trade Permit + 30-day notice for U.S.-origin AI chipsFirst host-state permit regime at a key transshipment node
Nov 19–20, 2025Commerce authorizes GB300-class exports to HUMAIN (Saudi Arabia) and G42 (UAE) under security conditionsTrusted-hub model formalized; Gulf compute corridor opens
Dec 2025Partial relaxation permits certain H200-class exports to China; McCormick–Wyden Remote Access Security Act introducedPhysical channel partially reopens while cloud gap is named in legislation
Jan 15, 2026BIS final rule: China/Macau shipments capped at ≤50% of exporter’s U.S.-bound volume per productQuantitative rationing layered onto licensing
Jan 2026Chinese customs block H200 entries despite licenses; Beijing steers buyers to domestic siliconCounter-control: Beijing asserts its own gate
Mar 19–26, 2026Super Micro co-founder arrested; Congress advances Chip Security Act (location verification)Enforcement escalates; hardware-level verification enters law-making
May 20, 2026Nvidia FY2027 Q1: $81.6B revenue; guidance assumes zero China data-center revenueMarket prices in durable bifurcation
May 31, 2026BIS weekend guidance: license follows headquarters / ultimate parent, wherever entity sits; installed base grandfatheredSubsidiary loophole formally closed prospectively; legacy compute pool locked in
Jun–Jul 2026Nvidia culls >50% of Asian buyers; conducts physical data-center audits in Singapore, Malaysia, JapanPrivate sector absorbs forensic-compliance burden

The oscillation recorded in Table 3 is not incidental noise around a stable policy; it is the policy environment, and it is itself a driver of evasion. Every reversal created an arbitrage window; every window was used; every use produced a corrective that created the next window. A control system that changes direction seven times in eighteen months teaches the regulated ecosystem a single durable lesson — that rules are temporary but installed hardware is forever — and thereby maximizes the incentive to acquire first and litigate later. This is the environment into which Section 4 now descends, at ground level, in Southeast Asia.


Section 4: Transshipment Realities — Case Studies in Southeast Asia

Abstractions must eventually touch the ground, and in this subject the ground is Southeast Asia. No region better illustrates the collision between the legacy control model and the disaggregated corporate reality, because no region combines, in the same square kilometers, a legitimate multi-decade semiconductor industry, a construction boom in AI data centers financed from every direction at once, a dense mesh of Chinese-linked corporate subsidiaries, and customs authorities asked — with no treaty obligation and limited resources — to enforce another sovereign’s technology strategy. This section proceeds from the scale problem, through the Malaysian infrastructure record and its emblematic cases, to the enforcement friction experienced by regional authorities, treating each with the granularity the public record now permits. The purpose is not to indict Malaysia or its neighbors — who are, in an important sense, the objects rather than the authors of this story — but to demonstrate empirically that every mechanism theorized in Sections 1 through 3 has already operated, at scale, on observable territory.


4.1 The Scale Problem: What the Investigative Record Shows

Begin with magnitudes, because they discipline everything else. Reuters’ May 31, 2026 reporting — the proximate trigger of the BIS guidance — relayed a chip-industry estimate that the flow of advanced processors to overseas subsidiaries of Chinese firms during the vacuum year ran to the hundreds of thousands of units[2]. For calibration: a single hyperscale training cluster of 100,000 modern accelerators represents multi-billion-dollar capital deployment and frontier-model training capability; the alleged leakage therefore corresponds not to marginal seepage but to several frontier-scale installations’ worth of compute. The Financial Times, in reporting cited before Congress, documented more than $1 billion of controlled Nvidia processors reaching China in a single three-month window through smuggling channels alone[8] — a figure that excludes the lawful-subsidiary channel entirely. Bloomberg’s review of Chinese government documents found domestic plans to install more than 115,000 restricted accelerators across three dozen data centers in China’s western provinces, including Xinjiang, with no lawful import path identified[29]. And at the level of criminal enforcement, the late-2025 Operation Gatekeeper conviction — the first in a U.S. AI-technology smuggling case — established $160 million of H100/H200 diversion by a single Texas-based operation over roughly seven months[21]. Individually, each datum is contestable; collectively, they describe a channel system whose aggregate throughput rivals the official export market for the same silicon.

Gregory Allen of CSIS — whose enforcement-capacity work has long warned that BIS’s budget is mismatched to its mission[30] — supplied the economic explanation for why the channels keep filling:

“the profit margins rival narcotics trafficking” [31]

— Gregory C. Allen, Director, Wadhwani Center for AI and Advanced Technologies, CSIS  [31]

A chip purchased at $25,000 and resold across the restriction line at $50,000 or more, with minimal detection risk, generates smuggling economics that guarantee professionalization[31] — and Allen’s congressional testimony had already documented, in the Russia-sanctions context, how such networks industrialize faster than the enforcement agencies chasing them[32]. Nvidia’s leadership, it should be recorded, has consistently disputed the scale narrative, with CEO Jensen Huang publicly insisting there is no evidence of AI-chip diversion — a position that drew sharp responses from researchers such as Samuel Hammond of the Foundation for American Innovation, whose March 2025 report on Chinese chip smuggling prompted, by his account, an immediate audience with the company[28]. The reader may weigh the incentives on each side; the documentary record assembled above does not depend on either party’s characterization.


4.2 Malaysian Infrastructure: The Emblematic Cases

Malaysia entered 2025 intending to climb the semiconductor value chain — to graduate from its fifty-year role in assembly, test, and packaging into AI infrastructure and chip design — and instead found itself, within eighteen months, at the geometric center of the global evasion debate[25]. Three cases define the record.


The Singapore server-fraud case (March 2025). Singaporean authorities charged three men — Chinese national Li Ming and Singaporeans Alan Wei Zhaolun and Aaron Woon Guo Jie — with fraud in connection with Dell and Supermicro servers exported from Singapore to Malaysia that may have contained high-performance Nvidia accelerators subject to U.S. controls; bail was set at up to S$1 million as investigations widened[33]. Singapore’s then-Home Affairs Minister K. Shanmugam publicly acknowledged that the servers exported to Malaysia might have been destined for a different final destination altogether[34] — the transshipment inference made, unusually, by the transit state itself. The case matters less for its (still-pending) outcome than for what it revealed procedurally: the alleged scheme was detected as fraud against vendors — misrepresentation on end-user declarations — rather than by any customs interdiction, confirming that the paperwork layer, not the border layer, is where such schemes surface when they surface at all.


The suitcase episode (reported June 2025). The Wall Street Journal reported that in March 2025, four Chinese engineers flew from Beijing to Kuala Lumpur, each carrying a suitcase containing fifteen hard drives — roughly 4.8 petabytes in aggregate — of spreadsheets, images, and video for AI training; their employer had arranged, months in advance, the rental of approximately 300 Nvidia-accelerated servers at a Malaysian data center, with the lease signed by the company’s Singapore-registered subsidiary, and the plan was to train the model locally and carry the finished weights home[35]. The drives were divided among four travelers precisely to avoid attracting customs attention, and the data flew rather than moving over the network because a multi-petabyte transfer would have taken conspicuous months[35]. Every element of this paper’s framework appears in the episode in miniature: no controlled item crossed any border; the corporate counterparty was a lawful third-country subsidiary; the workload was controlled by nationals of the restricted jurisdiction; and the benefit — the trained model — exited in carry-on luggage. Asia Times’ summary of the Journal’s reporting drew the systemic conclusion: U.S. regulation concentrated on physical chip exports while leaving cloud-based computing power ungoverned, and Chinese firms leveraged the gap effectively[36].


The Megaspeed investigation (2025–2026). Bloomberg’s investigation of Megaspeed — a Singapore-based cloud provider that became Nvidia’s largest Southeast Asian buyer within roughly three years — traced the company’s roots to a Chinese gaming firm, linked it to more than $2 billion in potential orders, and identified discrepancies between the volume of chips imported and the capacity of its disclosed data-center footprint; U.S. and Singaporean authorities have examined whether the company served as a conduit for restricted hardware ultimately destined for China, with its Malaysian subsidiary reportedly purchasing for data centers in Malaysia and Indonesia serving Chinese clients[21]. Megaspeed exemplifies the hardest category in the whole taxonomy — the structurally real intermediary: incorporated in a trusted jurisdiction, commercially substantial, and nonetheless under investigation as a channel. It is the case the Entity List cannot anticipate and the shipping address cannot reveal.


Table 4 — Southeast Asian Case Record, 2025–2026: Mechanisms and Lessons

CaseMechanism of EvasionDetection VectorFramework Lesson
Singapore server-fraud prosecution (Li, Wei, Woon)Misdeclared end-users; servers exported Singapore → Malaysia; possible onward destinationVendor fraud investigation, not customs interdictionThe paperwork layer, not the border, is where schemes surface
WSJ “suitcase” episodeData flown in; compute rented locally; lease via Singapore subsidiary; weights carried homeInvestigative journalism onlyWorkload evasion requires no controlled shipment at all
Megaspeed investigationRapid rise of a real Singapore cloud buyer with Chinese corporate roots; import volumes exceed disclosed capacityBloomberg investigation; U.S./Singapore inquiriesStructurally real intermediaries defeat list-based screening
Operation Gatekeeper (Hao Global conviction)Falsified shipping documents; relabeled H100/H200 hardware; $160M over ~7 monthsDOJ criminal enforcementClassical smuggling persists alongside corporate-layer evasion
Super Micro co-founder indictment (Mar 2026)Servers diverted via Taiwan and Southeast Asian shells; dummy equipment staged to pass auditsFBI investigationAudit-defeating countermeasures are now standard tradecraft
Malaysian free-trade-zone seizure (2026)AI servers declared as “computer components”; FTZ transit used to strip originMalaysian customs, post-Directive 1/2025Host-state permit regimes can work — when resourced and motivated

4.3 Local Enforcement Friction: Foreign Rules Under Domestic Frameworks

The third dimension of the Southeast Asian record is institutional: what happens when regional authorities are asked to enforce, in substance, another country’s technology-control strategy through their own domestic trade law. Malaysia’s answer came on July 14, 2025, when the Ministry of Investment, Trade and Industry issued Directive No. 1/2025 under the catch-all provision of Section 12 of the Strategic Trade Act 2010, requiring — with immediate effect — a Strategic Trade Permit and thirty days’ advance notification for the export, transshipment, or transit of high-performance AI chips of U.S. origin, pending review of their formal inclusion on the Strategic Items List[17]. The ministry framed the directive as closing regulatory gaps, and its accompanying statement was unambiguous about intent:

“stands firm against any attempt to circumvent export controls” [17]

— Ministry of Investment, Trade and Industry (MITI), Government of Malaysia, official press statement, July 14, 2025  [17]

Legal analysis of the directive noted its careful construction: the operative text nowhere names the United States, resting instead on Malaysia’s existing end-use and end-user logic concerning restricted activities — a drafting choice that preserves formal neutrality while functionally answering Washington’s pressure[37]. The sequence of that pressure is documented: U.S. plans to tighten rules specifically for Malaysia and Thailand had been reported earlier in July 2025[34], following Washington’s January 2025 investigation of Singapore transit routes and the Shanmugam disclosure[34], and the directive landed weeks after Malaysia had publicly affirmed its stance amid the allegations that Chinese engineers had rented Nvidia-dense local capacity to train models[38].

The friction, however, is structural and remains unresolved. Malaysia’s customs and trade apparatus must now adjudicate, shipment by shipment, questions — ultimate parentage, suspected end-use, re-export intent — that the world’s best-resourced enforcement agency, BIS, struggles to adjudicate with a budget Allen and colleagues have shown to be a rounding error against its mission[30]. The host state carries the administrative cost of a control regime whose strategic benefit accrues elsewhere, while simultaneously courting the data-center foreign direct investment — from American hyperscalers and Chinese platforms alike — that the same regime endangers. Directive 1/2025 is therefore best read not as the solution to transshipment but as the precedent for the multilateral alignment this paper’s fifth pillar develops: proof that a transit state will build permit machinery when the reputational and market stakes are made concrete, and proof, equally, that no transit state can carry the verification burden alone. The 2026 free-trade-zone seizure of mis-declared AI servers — caught by Malaysian officers applying the new regime[21] — shows the machinery beginning to function; the continuing investigations catalogued above show how much flows past it.


Section 5: Geopolitical Lawfare and Counter-Escalations

Export controls do not operate on a passive world. Every extension of jurisdiction summons three responses: the strategic relocation of activity to jurisdictions the rule treats favorably; the sovereign discomfort of intermediary states squeezed between the controlling power and its target; and the counter-regulation of the targeted power, which builds mirror-image instruments of its own. This section examines all three, because the Export Evasion framework is incomplete if it treats evasion as a one-sided pathology of the controlled rather than a dynamic equilibrium among sovereigns. The deep point of the section is that the world is not dividing into a controlled zone and an uncontrolled zone; it is dividing into overlapping extraterritorial claims — American rules that follow ownership outward, Chinese rules that follow materials and components outward — with the intermediary states and multinational firms caught in the interference pattern between them.


5.1 Strategic Hubbing: The Gulf Model and the Neutral-Territory Compute Boom

The first response to jurisdictional pressure is relocation — not evasion in the shadowed sense, but the open, state-sponsored construction of compute capacity in territories positioned as trusted intermediaries. The Gulf is the paradigm. Under the compute-diplomacy framework consolidated during the May 2025 presidential visit to the region, the United States and the United Arab Emirates launched an AI Acceleration Partnership anchored by Stargate UAE — a one-gigawatt cluster within a planned five-gigawatt campus in Abu Dhabi, built by G42 with OpenAI, Oracle, Nvidia, Cisco, and SoftBank, its first 200 megawatts scheduled online in 2026 — while reports indicated a framework allowing the UAE to import as many as 500,000 advanced accelerators annually[39]. On November 19–20, 2025, following the Saudi Crown Prince’s Washington visit, the Commerce Department authorized initial exports of GB300-class hardware to Saudi Arabia’s HUMAIN and the UAE’s G42, conditioned on rigorous security and reporting requirements[40]. HUMAIN’s chief executive announced the ambition with characteristic Gulf velocity:

“build the capacity equivalent to what Saudi has built in the last 20 years” [41]

— Tareq Amin, CEO of HUMAIN (Saudi Arabia), at the U.S.-Saudi Investment Forum, November 2025  [41]

— in a single year[41]. The Gulf model is, in one reading, the answer to Export Evasion: rather than pretending the border can hold, it conditions massive lawful access on verifiable security arrangements — G42’s divestment from Chinese hardware partnerships and its shedding of Chinese equity stakes were explicit predicates for Microsoft’s $1.5 billion investment and the subsequent export authorizations[42]. In another reading, it is the globalization of the risk surface this paper describes: hundreds of thousands of frontier accelerators per year deployed into sovereign territories whose ultimate strategic alignment is a diplomatic variable, governed by security addenda whose contents remain largely unpublished[40]. Both readings are correct, and the tension between them is precisely why Section 6’s pillars insist on verification machinery — ledgering, attestation, audit — that does not depend on the good faith of any single government, including America’s own. Strategic hubbing, meanwhile, is not confined to allies: the intentional growth of data-center networks in formally neutral jurisdictions — Southeast Asia, Central Asia, the wider Middle East — allows actors of every flag to tap advanced compute without setting foot in restricted territory, and the WSJ-documented migration of Chinese data-processing to Southeast Asian and Middle Eastern facilities after smuggling grew harder shows the two hub types functioning as substitutes on a single continuum[36].


5.2 Sovereign Friction: Intermediary States Between FDI and Compliance

The second response belongs to the intermediary states, and it is best described as a permanent condition of dual solicitation. Malaysia is again the clarifying case. The same eighteen months that produced Directive 1/2025 produced record data-center investment commitments into Johor from American, Chinese, and regional capital simultaneously; the same government that pledged to stand firm against circumvention was contending with a Tier-2 classification under the (rescinded) AI Diffusion Rule that would have capped its national accelerator imports at 50,000 units over two years — a ceiling incompatible with its hub ambitions[25]. The structural position of such states is not hypocrisy; it is arithmetic. Compliance with the controlling power protects access to the silicon and to the hyperscaler investment; accommodation of the targeted power protects the export markets and construction capital on which the domestic economy runs. Singapore’s simultaneous prosecution of the server-fraud defendants[33] and continued courtship of both American and Chinese cloud investment displays the same double motion. The IMF’s fragmentation research identifies exactly these economies — the connector states — as bearing the largest proportional losses when blocs harden, because their entire development model is the arbitrage the blocs are trying to eliminate[18]. Sovereign friction, in other words, is not a temporary diplomatic irritation to be managed; it is the durable geopolitical price of extraterritorial control, and any framework — like this paper’s — that proposes deeper extraterritoriality must budget for it explicitly, through burden-sharing rather than pressure alone.


5.3 Counter-Regulatory Responses: Beijing’s Mirror Arsenal

The third response is the most consequential for the long run: the targeted power has built a mirror-image control system of its own, and since 2025 has begun operating it with confidence. The architecture assembled by Beijing since 2020 now comprises: the Export Control Law of 2020 and its 2024 implementing regulations; the January 2021 blocking rules designed to counter the extraterritorial reach of foreign sanctions[43]; the Anti-Foreign Sanctions Law, wielded against U.S. defense firms; the Unreliable Entity List, which by 2025 had moved from theoretical threat to working tool, sweeping in American drone makers, apparel groups, and biotechnology firms[44]; and an anti-monopoly apparatus deployed for retaliatory effect, including the antitrust probe of Nvidia opened in the wake of U.S. chip controls[44]. The rare-earth campaign of 2025 marked the qualitative escalation: April 2025 licensing controls on seven medium and heavy rare-earth elements in direct response to U.S. tariff action[45], followed in October 2025 by measures that, for the first time, applied a foreign-direct-product logic — the mechanism Washington itself pioneered — to Chinese-origin rare-earth content abroad, alongside a 50-percent ownership rule extending Chinese jurisdiction through corporate chains[46]. The mirror could hardly be more exact: as America’s rules began following ownership outward, China’s rules began following materials outward, each claiming jurisdiction over conduct on the other’s side of the planet.

The November 2025 Busan understanding — under which Beijing delayed parts of the October package for a year while Washington suspended its own rule extending controls to subsidiaries of listed Chinese firms[47] — demonstrated that these mirrored instruments are now standing negotiating chips, calibrated rather than abolished. And January 2026 demonstrated something stranger and more revealing: Chinese customs authorities blocked licensed H200 imports and quietly instructed domestic champions to halt orders, steering them toward domestic silicon even at a near-term performance cost[48] — the targeted state, in effect, imposing on itself the very denial the controls intended, in order to escape the chokehold permanently. The commercial consequences registered within the quarter. Nvidia’s fiscal 2027 first-quarter results — the latest earnings data available through calendar Q2 2026 — recorded revenue of $81.6 billion, up 85 percent year over year, with data-center revenue of $75.2 billion; yet Hopper-class data-center shipments to China were zero, against $4.6 billion in the prior-year quarter, and the company’s $91 billion guidance for the following quarter assumed no China data-center compute revenue whatsoever[49]. Chief Executive Jensen Huang told financial media he had

“largely conceded” [48]

— Jensen Huang, CEO of NVIDIA, remarks to CNBC following Q1 FY2027 results, May 2026  [48]

the Chinese data-center market to Huawei — while hyperscaler capital expenditure outside China, projected by Evercore and Bank of America to exceed $1 trillion, absorbed every accelerator the company could ship[50]. A Forrester analyst summarized the market’s verdict: demand outside China is more than sufficient to sustain growth[48]. The earnings tape thus records, in a single filing, the completed bifurcation this section describes — and records, too, its cost: a $150-billion-class terminal market surrendered by decree, without a treaty, a WTO case, or a shot[48].


Table 5 — Mirror Instruments: U.S. Extension vs. Chinese Counter-Extension

FunctionU.S. InstrumentChinese Counterpart
Follow the technology abroadForeign Direct Product Rule (incl. Footnote 5 regime, Dec. 2024)Oct. 2025 rare-earth FDPR-style controls on Chinese-origin content abroad
Follow the corporate chainMay 31, 2026 headquarters / ultimate-parent guidance50-percent ownership rule extending jurisdiction through affiliates
Name hostile entitiesEntity List; 1260H military-company listUnreliable Entity List; Anti-Foreign Sanctions Law designations
Neutralize the other side’s reachSanctions on evasion networks; DOJ prosecutionsJan. 2021 blocking rules; data-security and cybersecurity review regimes
Weaponize a chokepointAdvanced accelerators, EDA tools, manufacturing equipmentRare earths, gallium, germanium, magnet supply (≈89% of global refining)
Retaliatory market denialLicense denials; 50% shipment-ratio cap (Jan. 2026)Customs blocks on licensed H200 imports; informal buy-domestic direction (Jan. 2026)

The counter-escalation record forces a sober conclusion onto the rest of the paper: any proposal that extends control must now be evaluated against the certainty of a symmetrical response. Chris Miller — reflecting at Carnegie Mellon in 2026 on where the diffusion of computing ultimately leads — reminded his audience that the dependency is only deepening:

“put more of these capabilities in an ever-larger number of our devices” [51]

— Chris Miller, Professor, Fletcher School, Tufts University — lecture at Carnegie Mellon University, 2026  [51]

A world in which compute saturates everything is a world in which mirrored extraterritorial regimes touch everything — which is why the institutional architecture of Section 6 aims not at maximal restriction but at verifiable restriction, narrow enough to hold and instrumented enough to check.


Section 6: What Have We Learned? Core Findings and the Six Institutional Pillars

The preceding five sections assembled a factual and analytical record; this section converts it into doctrine. It proceeds in two movements. The first states, as compactly as honesty allows, the three structural lessons the 2020–2026 record teaches — lessons about arbitrage, about the sequencing of scale and enforcement, and about the arithmetic of grandfathering. The second builds the affirmative program: six institutional pillars, ordered so that each supplies what its predecessor lacks, and culminating in the Beneficial Workload Rule — the doctrinal keystone that re-attaches jurisdiction to the thing that actually matters, which is not the box, not the address, and not even the owner of record, but the operational benefit of the computation itself.


6.1 Three Structural Lessons

Lesson one — jurisdictional arbitrage is the default, not the exception. Legacy export rules are fundamentally blind to post-import leasing models, cloud workloads, and multi-layered shell entities, because every one of those structures lives after and behind the events the rules observe. The record of Sections 2 and 4 shows arbitrage operating simultaneously at every layer — corporate (nested parents), financial (offshore leasing), physical (free-trade-zone transit), and computational (rented clusters, flown-in data). Wherever two jurisdictions treat the same function differently, the function migrates to the friendlier one; the migration is usually lawful; and its aggregate effect is indistinguishable, strategically, from smuggling. A control system that cannot see arbitrage cannot see most of the phenomenon.


Lesson two — scale precedes enforcement. In every documented episode, high-performance hardware reached critical operational mass abroad before the watchlists, guidance documents, or permit regimes adjusted: the subsidiary channel moved hundreds of thousands of units in the vacuum year before the May 2026 guidance named it[2]; Megaspeed became a top regional buyer years before investigators mapped its lineage[21]; the suitcase training run was complete before any regulator knew it had begun[35]. The asymmetry is structural: acquisition operates at commercial speed, enforcement at bureaucratic speed, and the gap between them — twelve to twenty-four months in the observed cases — is longer than a hardware generation. Any regime whose response time exceeds the adversary’s acquisition time will always be regulating the previous episode.


Lesson three — grandfathering is not neutrality; it is allocation. The May 2026 choice to leave installed hardware running and serviceable[2] converted the entire leaked stock into a protected asset class. Massive compute pools remain active and accessible for training cutting-edge networks, refreshed by permitted maintenance, for the useful life of the silicon — and the precedent teaches every future actor that whatever crosses before the next rule will keep what it grabbed. A regime that cannot reach the installed base has, in effect, announced that its rules are prospective suggestions with a race condition.


Pillar 1: Ultimate Beneficial Ownership (UBO) Transparency

The first pillar answers the first question of the Export Evasion test — who owns the customer? — and it must come first because every subsequent pillar consumes its output. The May 2026 guidance made ultimate parentage the jurisdictional trigger[1]; a trigger is only as good as the registry that can pull it. The pillar therefore mandates strict, verified, and internationally reconciled beneficial-ownership registration for any entity transacting in covered items or covered compute above defined thresholds: registry verification (not mere self-declaration) tracing entity hierarchies through every intermediate screen to natural-person or ultimate-parent termination; refresh obligations on ownership change; and cross-recognition agreements so that a Malaysian permit officer, a Singaporean prosecutor, and an American licensing officer are reading the same chain. The direction of current policy must be candidly reversed: the Treasury’s March 2025 retreat from Corporate Transparency Act enforcement[23] and the ownership-information gaps the GAO has since documented[24] are directly incompatible with a parentage-triggered control regime — one arm of the state is demanding lineage data the other arm has stopped collecting. FATF-grade UBO infrastructure is no longer an anti-money-laundering nicety; it is the foundation layer of technology control.


Pillar 2: Cloud-Level Know-Your-Customer (KYC) Frameworks

The second pillar answers questions three and four — who operates the cluster, and who controls the workloads? — by extending controls into the layer where the suitcase episode and every rented-cluster variant actually live. Building on the January 2024 proposed IaaS rule and the scholarly designs of Egan, Heim, and the CSET program[13], the pillar requires providers of large computing blocks — wherever incorporated, if they deploy covered U.S.-origin accelerators — to verify the ultimate headquarters of entities renting above-threshold capacity, to apply the same parentage test the hardware sale now carries, and to report sustained large-scale training usage by covered entities. The design must honor what the literature established early: cloud access is a more precise control surface than hardware export, because it can be metered, throttled, and revoked in real time rather than lost forever at the border[13]; a blanket ban is therefore both unnecessary and counterproductive, ceding the market while forfeiting the visibility. The Remote Access Security Act supplies the missing statutory authority — extending the Export Control Reform Act to remote access itself[16] — and should be enacted; but statute without operational KYC is a trigger without a registry, which is why Pillars 1 and 2 are designed as a pair.


Pillar 3: Multilateral Tech-Sovereign Alignment

The third pillar addresses the sovereign-friction findings of Sections 4 and 5: no unilateral regime can police a lattice that runs through forty registries and a dozen transit hubs, and Wassenaar — wrong members, wrong speed, wrong categories — cannot be retrofitted for the task. The pillar therefore proposes a compact, purpose-built alignment among the states that actually constitute the advanced-compute map: the supply-chain states (the United States, Taiwan, Japan, the Netherlands, Korea), the hub states (Malaysia, Singapore, the UAE, Saudi Arabia, and successors), and willing demand states. Its working content is harmonization — shared technical definitions of covered compute; mutual recognition of permits and UBO determinations; joint watch-desks for transshipment intelligence; and, critically, burden-sharing: financing, training, and secondment for the customs and trade ministries now carrying enforcement loads their budgets were never built for. Malaysia’s Directive 1/2025 is the proof of concept — a hub state building real permit machinery under combined reputational and market pressure[17] — and the Gulf security addenda are the proof that conditional access can purchase alignment[40]; the pillar generalizes both precedents into standing architecture, so that alignment no longer depends on episodic bilateral pressure applied after each scandal.


Pillar 4: Continuous Hardware Asset Ledgering

The fourth pillar supplies what every paper-based pillar lacks: ground truth. It mandates secure, device-level, root-of-trust–anchored tracking of covered accelerators — a continuously reconciled ledger of where each high-performance component is, in whose custody, and in what configuration — for the operational life of the device. The technical foundation already ships: modern GPUs include remote-attestation capabilities, marketed for confidential computing and used by major cloud providers to verify workload integrity[52], and the Chip Security Act — which advanced through Congress in March 2026 with the arrests of that month at its back[22] — would require exported covered products to carry location-verification mechanisms, with exporters obligated to report credible evidence of diversion or tampering[53]. The legislative design is deliberately modest in ways this pillar endorses: verification runs on ping-based delay measurement rather than GPS surveillance, data remains with companies absent evidence of diversion, and kill-switches and geofencing are explicitly excluded[52]. Industry’s posture shifted across 2025–2026 from resistance to selective embrace — by June 2026, a coalition of tracking-technology firms was arguing to congressional leadership that verification would increase competitiveness by accelerating export approvals and enlarging permissible deals[54] — the compliance-as-market-access logic on which this pillar’s political economy depends. Ledgering also finally operationalizes question six of the test: a vendor cannot responsibly service what it cannot locate, and a serviced device that goes dark on the ledger is itself the red flag the legacy system never possessed.


Pillar 5: Proactive Post-Import Audits

The fifth pillar moves enforcement past the border in time as ledgering moves it past the border in space: joint verification mechanisms under which international regulatory bodies and host-state authorities audit data centers after installation, on a standing schedule and on triggered cause, to confirm that facilities match their corporate end-use claims — that the tenant of record is the operator in fact, that cluster occupancy matches the import ledger, and that workload patterns are consistent with declared use. The precedent again already exists in embryonic form: Nvidia’s 2026 compliance rebuild included physical data-center visits across Singapore, Malaysia, and Japan[21], and the Megaspeed inquiry turned decisively on exactly the discrepancy a routine audit would surface — imports exceeding disclosed capacity[21]. What is private and episodic must become institutional and regular, jointly staffed so that the audit is an exercise of the host state’s sovereignty rather than an affront to it, with continued vendor servicing (the grandfathering concession of May 2026) made conditional on audit access — converting the one lever the guidance preserved into the compliance instrument it should have been from the start.


Pillar 6: The Beneficial Workload Rule

The sixth pillar is the keystone, and it is this paper’s central affirmative proposal. All five preceding pillars instrument the system; the Beneficial Workload Rule tells the instrumented system what, finally, to measure. The rule can be stated in one sentence: export-control jurisdiction over advanced compute should attach to the party that derives the operational benefit of the workload, traced through ownership, financing, operational control, and output receipt — not solely to the legal title of the hardware or the location of the facility. Where the 2026 BIS guidance reached the first rung of the Export Evasion test (who owns the customer), the Beneficial Workload Rule ascends the remaining five: a covered determination would ask who financed the acquisition, who holds administrative control of the cluster, who directs what is trained and served, who receives the weights and outputs, and who sustains the machine — and would treat benefit to a restricted party on any rung as the licensing trigger, whatever the flags on the building, the invoice, or the parent registry.

The rule’s intellectual pedigree is deliberately borrowed from the two bodies of law that solved analogous problems a generation ago. From anti-money-laundering law it takes the concept of the beneficial owner — the recognition, hard-won through the Panama Papers era, that legal title is a costume and that regulation must address the wearer[23]. From international tax law it takes the substance-over-form and beneficial-ownership doctrines by which treaty benefits are denied to conduit entities that lack economic substance. Export control is simply the last of the great cross-border regimes to make this move, and the 2020–2026 record assembled in this paper is the demonstration of what its delay has cost. Administrability follows from the pillars: UBO registries (Pillar 1) supply the ownership rung; cloud KYC (Pillar 2) supplies the operation and workload rungs; ledgering (Pillar 4) and audits (Pillar 5) supply verification; multilateral alignment (Pillar 3) supplies reach. The rule is also, crucially, calibrated rather than maximal: a legitimate multinational subsidiary whose workloads demonstrably serve its own third-country business would license cleanly under it — more cleanly, indeed, than under today’s blunt parentage test — while the structurally real conduit, the rented cluster, and the flown-in training run would all, for the first time, be visible to the trigger. Precision, not breadth, is the design virtue: as Chris Miller has framed the underlying judgment for years,

“be very careful when deciding which countries and which companies we sell these to” [55]

— Chris Miller, Professor, Fletcher School, Tufts University, author of Chip War, on CNBC  [55]

— and care, at the frontier of 2026, means knowing not merely to whom one sells, but for whom the machine ultimately runs.


Table 6 — The Six Pillars: Function, Test Questions Answered, and Current Status

PillarCore FunctionTest Questions AnsweredNearest Existing Instrument (Status, July 2026)
1. UBO TransparencyVerified ownership chains to ultimate parentsQ1CTA / FinCEN registry (enforcement retrenched, 2025); FATF standards
2. Cloud-Level KYCParentage and usage vetting for large compute rentalsQ3, Q4Jan. 2024 proposed IaaS rule (unfinalized); Remote Access Security Act (pending)
3. Multilateral AlignmentShared definitions, permits, intelligence, burden-sharingAll (reach)Malaysia Directive 1/2025; Gulf security addenda (bilateral, episodic)
4. Hardware Asset LedgeringDevice-level location and configuration ground truthQ6 (and verification of Q3)Chip Security Act, H.R. 3447 (advancing, 2026); GPU remote attestation (shipping)
5. Post-Import AuditsStanding joint verification of facilities vs. claimsQ3, Q6Vendor site visits (private, 2026); Megaspeed-style investigations (reactive)
6. Beneficial Workload RuleJurisdiction attaches to operational benefitQ1–Q6May 31, 2026 BIS guidance (reaches Q1 only) — proposed extension, this paper

Conclusion:

Synthesis: The End of Geography as a Control Surface

This paper opened with a claim that would have sounded overwrought a decade ago and now reads as a description of the public record: geographic borders no longer serve as reliable barriers for controlling advanced hardware. The demonstration ran through six sections. The end-use and end-user frameworks inherited from CoCom and Wassenaar were built to observe a decisive border crossing that is no longer where the decisive events occur. The modern corporate group — disaggregated across holding companies, financing vehicles, purchasing subsidiaries, landlords, tenants, operators, and beneficiaries — has decoupled ownership from geography so thoroughly that the United States was compelled, in a two-page weekend notice, to redefine its jurisdictional trigger from the shipping address to the corporate bloodline[1]. The Southeast Asian record showed every theorized mechanism operating in the world: subsidiaries at scale, structurally real conduits, rented clusters, data in suitcases, and a host state improvising permit machinery under pressure from both superpowers at once. The counter-escalation record showed the targeted power building the mirror image — following materials outward as America follows ownership outward — until the world’s two largest economies each claim jurisdiction deep inside the other’s commercial space, with the connector states and a bifurcating market absorbing the cost that the IMF’s fragmentation research prices in points of global GDP[18]. Distributed corporate setups and remote-access models have not merely strained the old system; they have dissolved its unit of analysis.


Why “Export Evasion,” Once More

The naming argument of the Introduction can now be restated with the whole record behind it. This framework is called Export Evasion because what is being evaded is not, in the main, a checkpoint — it is jurisdiction: the rule’s reach, engineered around through structures that are individually lawful and collectively decisive. It is called Export Evasion because the phenomenon spans, without a seam, the criminal (falsified documents, relabeled crates, dummy audit hardware), the gray (nested parents, nominee boards, name-distance procurement), and the lawful (real subsidiaries, real tenants, real leases) — and because only a term that holds the whole spectrum can keep analysis honest about where the largest volumes actually flow. It is called Export Evasion because the phrase relocates the burden of proof from the border to the balance sheet, the registry, and the workload, which is where this paper has shown the truth to live. And it is called Export Evasion because the period this paper documents — the vacuum year, the hundreds of thousands of units, the grandfathered pastures, the floodgates that quietly opened — deserves a name that does not flatter it. Euphemism, in this field, is a form of complicity with the arbitrage.


Final Insight: Follow the Capital, the Lineage, and the Workload

The constructive conclusion is equally direct. To remain effective, export policy must complete the migration it has already, half-consciously, begun: away from tracking physical points of delivery, and toward tracing the flow of global corporate capital, parent-company lineage, and digital cloud workloads. The May 2026 guidance took the first step when it made lineage the trigger; the six pillars of Section 6 describe the remaining architecture — verified ownership registries, cloud-level KYC, multilateral burden-sharing, device-level ledgering, standing post-import audits — and the Beneficial Workload Rule states the destination: jurisdiction attaching, at last, to the party for whom the computation actually runs. None of this will be cheap, and Section 5 counsels against triumphalism: every extension will be mirrored, every burden will strain an intermediary state, and the economic gradient against which all of it works is measured in trillions. But the alternative — a control system that continues to interrogate the box while the benefit departs through the corporate registry and the network layer — has now been tested against reality for four years, and reality has returned its verdict in the enforcement record, the earnings filings, and the government’s own confessions. The border was a proxy. The proxy has failed. The task of the next decade is to regulate the thing itself: not where the machine lands, but whom the machine serves.


Footnotes / Endnotes:

[1] Washington Trade & Tariff Letter. “BIS Reasserts AI Chip License Rule for Chinese-Headquartered Firms Operating Abroad.” WTTL Online, June 5, 2026. https://www.wttlonline.com/stories/bis-reasserts-ai-chip-license-rule-for-chinese-headquartered-firms-operating-abroad,15216

[2] Karen Freifeld (Reuters). “U.S. takes step to halt Nvidia AI chip shipments to Chinese firms outside China.” Reuters via CNBC, May 31, 2026. https://www.cnbc.com/2026/05/31/us-takes-step-to-halt-nvidia-ai-chip-shipments-to-chinese-firms-outside-china.html

[3] Girish Sastry, Lennart Heim, Haydn Belfield, Markus Anderljung, Miles Brundage, Gillian K. Hadfield (University of Toronto), Yoshua Bengio (Université de Montréal), et al.. “Computing Power and the Governance of Artificial Intelligence.” Centre for the Governance of AI (GovAI), February 14, 2024. https://www.governance.ai/analysis/computing-power-and-the-governance-of-ai

[4] ExpertLancing (policy analysis). “How BIS Is Reshaping AI Chip Export Compliance.” ExpertLancing Policy & Regulatory Reform, June 2026. https://expertlancing.com/policy-regulatory-reform/bis-chip-export-controls-subsidiary-clarification/

[5] Reuters (Karen Freifeld). “US takes step to halt Nvidia AI chip shipments to Chinese firms outside China.” Reuters via Investing.com, May 31, 2026. https://m.investing.com/news/stock-market-news/us-takes-step-to-halt-nvidia-ai-chip-shipments-to-chinese-firms-outside-china-4717939

[6] Asia Times. “Nvidia GPU crackdown hits China-linked Southeast Asia data centers.” Asia Times, June 6, 2026. https://asiatimes.com/2026/06/nvidia-gpu-crackdown-hits-china-linked-southeast-asia-data-centers/

[7] Al Jazeera. “US says ban on AI chip shipments applies to Chinese firms outside China.” Al Jazeera Economy, June 1, 2026. https://www.aljazeera.com/economy/2026/6/1/us-says-ban-on-ai-chip-shipments-applies-to-chinese-firms-outside-china

[8] FDD Action (citing Financial Times and Reuters). “Action Alert: Support H.R. 3447, the Chip Security Act.” FDD Action, March 25, 2026. https://www.fddaction.org/action-alert/2026/03/25/action-alert-support-h-r-3447-the-chip-security-act-and-other-measures/

[9] Congressional Research Service. “U.S. Export Controls and China: Advanced Semiconductors (R48642).” Congress.gov / Library of Congress. https://www.congress.gov/crs-product/R48642

[10] Gregory C. Allen (CSIS). “Choking off China’s Access to the Future of AI.” Center for Strategic and International Studies, October 2022. https://www.csis.org/analysis/choking-chinas-access-future-ai

[11] GEOPOL (profile of Chris Miller). “Chris Miller: The Historian Who Made Chips Geopolitics.” GEOPOL, May 30, 2026. https://geopol.uk/thinkers/chris-miller/

[12] Hanna Dohmen, Jacob Feldgoise, Emily S. Weinstein, Timothy Fist (CSET, Georgetown University). “Controlling Access to Advanced Compute via the Cloud: Options for U.S. Policymakers, Part I.” Center for Security and Emerging Technology, Georgetown University. https://cset.georgetown.edu/article/controlling-access-to-advanced-compute-via-the-cloud/

[13] Janet Egan & Lennart Heim. “Oversight for Frontier AI through a Know-Your-Customer Scheme for Compute Providers.” arXiv:2310.13625, October 2023. https://arxiv.org/pdf/2310.13625

[14] Lennart Heim, Markus Anderljung, Haydn Belfield. “To Govern AI, We Must Govern Compute.” Lawfare, March 28, 2024 (indexed by MIT Political Science / CyberIR@MIT). https://www.lawfaremedia.org/article/to-govern-ai-we-must-govern-compute

[15] CSET, Georgetown University. “Controlling Access to Compute via the Cloud: Options for U.S. Policymakers, Part II.” Center for Security and Emerging Technology, Georgetown University. https://cset.georgetown.edu/article/controlling-access-to-compute-via-the-cloud-options-for-u-s-policymakers-part-ii/

[16] Office of Senator Dave McCormick (with Senator Ron Wyden). “Senators McCormick and Wyden Introduce Remote Access Security Act.” Press release, December 17, 2025. https://www.mccormick.senate.gov/?p=11427

[17] Ministry of Investment, Trade and Industry (MITI), Government of Malaysia. “Export, Transshipment and Transit of High-Performance AI Chips of US Origin Now Subject to a Strategic Trade Permit.” MITI Press Statement, July 14, 2025. https://www.miti.gov.my/miti/resources/Media%20Release/%5BFINAL%5D_MITI_Press_Stmt_Malaysia_Regulates_Trade_of_US_AI_Chips_2025-07-14.pdf

[18] Shekhar Aiyar, Andrea Presbitero, Michele Ruta, et al., International Monetary Fund. “Geoeconomic Fragmentation and the Future of Multilateralism (Staff Discussion Note SDN/2023/001).” International Monetary Fund, 2023. https://www.imf.org/-/media/files/publications/sdn/2023/english/sdnea2023001.pdf

[19] Gita Gopinath (IMF First Deputy Managing Director), at Stanford University (SIEPR). “IMF’s Gita Gopinath: Geopolitics and Its Impact on Global Trade and the Dollar.” Stanford Institute for Economic Policy Research, May 2024. https://siepr.stanford.edu/news/imfs-gita-gopinath-geopolitics-and-its-impact-global-trade-and-dollar

[20] Reuters via Nasdaq (quoting Gita Gopinath, IMF). “IMF’s Gopinath says economic fragmentation could cut global GDP by 7%.” Nasdaq, December 2023. https://www.nasdaq.com/articles/imfs-gopinath-says-economic-fragmentation-could-cut-global-gdp-by-7

[21] Tech Times. “Nvidia Cuts Over Half of Asian AI Chip Buyers as BIS Compliance Net Widens.” Tech Times, July 15, 2026. https://www.techtimes.com/articles/320527/20260715/nvidia-cuts-over-half-asian-ai-chip-buyers-bis-compliance-net-widens.htm

[22] Bloomsbury Intelligence and Security Institute (BISI). “AI Chip Smuggling: The Limits of US Export Controls.” BISI, April 6, 2026. https://bisi.org.uk/reports/ai-chip-smuggling-the-limits-of-us-export-controls

[23] International Consortium of Investigative Journalists (ICIJ). “Treasury Department won’t enforce beneficial ownership rule under the Corporate Transparency Act.” ICIJ, March 5, 2025. https://www.icij.org/inside-icij/2025/03/treasury-department-wont-enforce-beneficial-ownership-rule-under-the-corporate-transparency-act/

[24] U.S. Government Accountability Office (GAO). “Corporate Transparency: Treasury Should Address Gaps in Ownership Information Resulting from Expanded Exemptions (GAO-26-107967).” GAO, 2026. https://www.gao.gov/products/gao-26-107967

[25] The Edge Malaysia. “Climbing the semiconductor value chain amid geopolitical crosswinds.” The Edge Malaysia, January 14, 2026. https://theedgemalaysia.com/node/788175

[26] Morgan, Lewis & Bockius LLP. “BIS Revises Export Review Policy for Advanced AI Chips Destined for China and Macau.” Morgan Lewis LawFlash, January 16, 2026. https://www.morganlewis.com/pubs/2026/01/bis-revises-export-review-policy-for-advanced-ai-chips-destined-for-china-and-macau

[27] Reuters (via Yahoo Finance / Insider Monkey). “Chinese authorities confirm purchase approvals of 400,000+ NVIDIA H200 chips.” Reuters report of January 28, 2026. https://finance.yahoo.com/news/nvidia-nvda-h200-chips-key-054853576.html

[28] The Wire China (quoting Michael Kratsios, Gregory C. Allen, Samuel Hammond). “Walling Off China.” The Wire China, September 7, 2025. https://www.thewirechina.com/2025/09/07/walling-off-china/

[29] TipRanks (reporting on Bloomberg). “China Eyes 115,000 Banned Nvidia AI Chips for Massive Data Centers.” TipRanks News, 2025. https://www.tipranks.com/news/china-eyes-115000-banned-nvidia-ai-chips-for-massive-data-centers

[30] Gregory C. Allen (CSIS, Wadhwani Center for AI and Advanced Technologies). “Mismatch of Strategy and Budgets in AI Chip Export Controls.” Center for Strategic and International Studies, December 2024. https://www.csis.org/analysis/mismatch-strategy-and-budgets-ai-chip-export-controls

[31] Tech-Insider (quoting Gregory C. Allen, CSIS). “Super Micro $2.5B Chip Smuggling Case.” Tech-Insider.org, updated April 2026. https://tech-insider.org/super-micro-nvidia-chip-smuggling-china-2026/

[32] Gregory C. Allen, Congressional Testimony. “China’s Pursuit of Defense Technologies: Implications for U.S. and Multilateral Export Control Regimes.” U.S.-China Economic and Security Review Commission, 2023. https://www.uscc.gov/sites/default/files/2023-04/Gregory_Allen_Testimony.pdf

[33] Malay Mail / The Straits Times. “Singapore court sets RM3.28m bail for suspect in alleged Nvidia server export scheme to Malaysia.” Malay Mail, May 2, 2025. https://www.malaymail.com/news/singapore/2025/05/02/singapore-court-sets-rm328m-bail-for-suspect-in-alleged-nvidia-server-export-scheme-to-malaysia/175347

[34] Free Malaysia Today. “Malaysia tightens rules on export of US AI chips.” FMT, July 14, 2025. https://www.freemalaysiatoday.com/category/nation/2025/07/14/malaysia-tightens-rules-on-export-of-us-ai-chips

[35] Tom’s Hardware (reporting on The Wall Street Journal). “Chinese AI outfits smuggling suitcases full of hard drives to evade U.S. chip restrictions.” Tom’s Hardware, June 13, 2025. https://www.tomshardware.com/tech-industry/artificial-intelligence/chinese-ai-outfits-smuggling-suitcases-full-of-hard-drives-to-evade-u-s-chip-restrictions-training-ai-models-in-malaysia-using-rented-servers

[36] Asia Times (reporting on The Wall Street Journal). “US plans to tighten AI chip export rules for Malaysia, Thailand.” Asia Times, July 15, 2025. https://asiatimes.com/2025/07/us-plans-to-tighten-ai-chip-export-rules-for-malaysia-thailand/

[37] Baker McKenzie. “Malaysia Introduces New Export Control Directive for Advanced AI Chips.” Global Sanctions and Export Controls Blog, July 17, 2025. https://sanctionsnews.bakermckenzie.com/malaysia-introduces-new-export-control-directive-for-advanced-ai-chips/

[38] South China Morning Post. “Malaysia imposes trade permits for US-linked AI chip shipments.” SCMP, July 14, 2025. https://www.scmp.com/week-asia/economics/article/3318099/malaysia-imposes-trade-permits-us-linked-ai-chip-shipments

[39] Arab News. “The AI alliance rewriting Washington’s Gulf strategy.” Arab News, July 2026. https://www.arabnews.com/node/2651908/amp

[40] Middle East Institute. “US Authorizes Chips for the UAE, Saudi Arabia.” MEI Policy Memo, February 2026. https://mei.edu/policymemo/us-authorizes-chips-for-the-uae-saudi-arabia-2/

[41] CNBC. “U.S. greenlights AI chip exports to Gulf tech giants after Saudi Crown Prince’s Washington visit.” CNBC, November 20, 2025. https://www.cnbc.com/2025/11/20/us-approves-ai-chip-exports-to-gulf-after-saudi-crown-prince-visit.html

[42] Data Center Dynamics (DCD). “US and UAE plan to build 5GW AI data center campus, run by G42 and American hyperscalers.” DCD, 2025-2026. https://www.datacenterdynamics.com/en/news/us-and-uae-plan-to-build-5gw-ai-data-center-campus-run-by-g42-and-american-hyperscalers/

[43] Congressional Research Service. “China’s Recent Trade Measures and Countermeasures: Issues for Congress (R46915).” Congress.gov / Library of Congress. https://www.congress.gov/crs-product/R46915

[44] CNBC (op-ed). “With new rare earth restrictions, it’s time for U.S. market to get real about the future threat of Chinese lawfare.” CNBC, October 9, 2025. https://www.cnbc.com/2025/10/09/china-rare-earth-metals-restriction-us-market-economy.html

[45] Holland & Knight LLP. “China’s Comprehensive Retaliation Against U.S. Tariffs.” Holland & Knight Insights, April 2025. https://www.hklaw.com/en/insights/publications/2025/04/chinas-comprehensive-retaliation-against-us-tariffs

[46] Center for Strategic and International Studies (CSIS). “China’s New Rare Earth and Magnet Restrictions Threaten U.S. Defense Supply Chains.” CSIS, October 14, 2025. https://www.csis.org/analysis/chinas-new-rare-earth-and-magnet-restrictions-threaten-us-defense-supply-chains

[47] Foundation for Defense of Democracies (FDD). “China Pauses Some Rare Earth Export Curbs While Retaining Levers of Control.” FDD Analysis, November 12, 2025. https://www.fdd.org/analysis/2025/11/12/china-pauses-some-rare-earth-export-curbs-while-retaining-levers-of-control/

[48] Model Diplomat. “US AI Chip Export Controls Tighten.” Model Diplomat, July 2026. https://modeldiplomat.com/story/us-ai-chip-export-controls-tighten

[49] NVIDIA Corporation (SEC Form 8-K). “NVIDIA Announces Financial Results for First Quarter Fiscal 2027.” SEC filing via StockTitan, May 20, 2026. https://www.stocktitan.net/sec-filings/NVDA/8-k-nvidia-corp-reports-material-event-56086a88bbb4.html

[50] CNBC. “Nvidia earnings takeaways: Data center revenue nearly doubles (Q1 FY2027).” CNBC, May 20-21, 2026. https://www.cnbc.com/2026/05/20/nvidia-nvda-earnings-report-q1-2027.html

[51] Chris Miller, lecture at Carnegie Mellon University (CMIST). “Chips and Chokepoints: Chris Miller on the Geopolitics of the AI Supply Chain.” Carnegie Mellon Institute for Strategy & Technology, March 2026. https://www.cmu.edu/cmist/news-archive/news/2026/march/chips-and-chokepoints-chris-miller-on-the-geopolitics-of-the-ai-supply-chain.html

[52] CAIS Action Fund. “The Chip Security Act: Separating Fact From Fiction.” Center for AI Safety Action Fund. https://action.safe.ai/news/the-chip-security-act-separating-fact-from-fiction

[53] U.S. Congress, 119th Congress. “H.R. 3447 — Chip Security Act (bill text).” Congress.gov / Library of Congress. https://www.congress.gov/bill/119th-congress/house-bill/3447/text

[54] NBC News. “Bill that would mandate AI chip location tracking gains industry support.” NBC News, June 18, 2026. https://www.nbcnews.com/tech/tech-news/chips-security-act-gains-industry-support-letter-rcna350500

[55] Chris Miller (Tufts University, Fletcher School). “’Chip War’ author Chris Miller on the battle of AI chip export controls.” CNBC Squawk Box, December 12, 2025. https://www.cnbc.com/video/2025/12/12/chip-war-author-chris-miller-on-the-battle-of-ai-chip-export-controls.html